diff --git a/advisories/github-reviewed/2019/06/GHSA-6cc5-2vg4-cc7m/GHSA-6cc5-2vg4-cc7m.json b/advisories/github-reviewed/2019/06/GHSA-6cc5-2vg4-cc7m/GHSA-6cc5-2vg4-cc7m.json index 7612a99a632..a9b260d0b7f 100644 --- a/advisories/github-reviewed/2019/06/GHSA-6cc5-2vg4-cc7m/GHSA-6cc5-2vg4-cc7m.json +++ b/advisories/github-reviewed/2019/06/GHSA-6cc5-2vg4-cc7m/GHSA-6cc5-2vg4-cc7m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6cc5-2vg4-cc7m", - "modified": "2024-11-18T22:11:28Z", + "modified": "2024-11-25T18:33:21Z", "published": "2019-06-10T18:05:06Z", "aliases": [ "CVE-2019-12387" @@ -64,6 +64,10 @@ "type": "WEB", "url": "https://labs.twistedmatrix.com/2019/06/twisted-1921-released.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2G5RPDQ4BNB336HL6WW5ZJ344MAWNN7N" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2G5RPDQ4BNB336HL6WW5ZJ344MAWNN7N" diff --git a/advisories/github-reviewed/2019/08/GHSA-65rm-h285-5cc5/GHSA-65rm-h285-5cc5.json b/advisories/github-reviewed/2019/08/GHSA-65rm-h285-5cc5/GHSA-65rm-h285-5cc5.json index 421bba6d92c..b8c8b5a0b9f 100644 --- a/advisories/github-reviewed/2019/08/GHSA-65rm-h285-5cc5/GHSA-65rm-h285-5cc5.json +++ b/advisories/github-reviewed/2019/08/GHSA-65rm-h285-5cc5/GHSA-65rm-h285-5cc5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-65rm-h285-5cc5", - "modified": "2024-11-18T22:12:13Z", + "modified": "2024-11-25T18:33:21Z", "published": "2019-08-16T14:02:35Z", "aliases": [ "CVE-2019-12855" @@ -60,6 +60,10 @@ "type": "PACKAGE", "url": "https://github.com/twisted/twisted" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PLTZDMFBNFSJMBXYJNGJHENJA4H2TSMZ" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PLTZDMFBNFSJMBXYJNGJHENJA4H2TSMZ" diff --git a/advisories/github-reviewed/2020/03/GHSA-h96w-mmrf-2h6v/GHSA-h96w-mmrf-2h6v.json b/advisories/github-reviewed/2020/03/GHSA-h96w-mmrf-2h6v/GHSA-h96w-mmrf-2h6v.json index d98f4c14384..7356a97ef69 100644 --- a/advisories/github-reviewed/2020/03/GHSA-h96w-mmrf-2h6v/GHSA-h96w-mmrf-2h6v.json +++ b/advisories/github-reviewed/2020/03/GHSA-h96w-mmrf-2h6v/GHSA-h96w-mmrf-2h6v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h96w-mmrf-2h6v", - "modified": "2024-11-18T22:30:00Z", + "modified": "2024-11-25T18:33:22Z", "published": "2020-03-31T15:42:42Z", "aliases": [ "CVE-2020-10108" @@ -72,6 +72,14 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2022/02/msg00021.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6ISMZFZBWW4EV6ETJGXAYIXN3AT7GBPL" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YW3NIL7VXSGJND2Q4BSXM3CFTAFU6T7D" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6ISMZFZBWW4EV6ETJGXAYIXN3AT7GBPL" diff --git a/advisories/github-reviewed/2020/03/GHSA-p5xh-vx83-mxcj/GHSA-p5xh-vx83-mxcj.json b/advisories/github-reviewed/2020/03/GHSA-p5xh-vx83-mxcj/GHSA-p5xh-vx83-mxcj.json index 0578e9bd98c..3e0c6c9c9e8 100644 --- a/advisories/github-reviewed/2020/03/GHSA-p5xh-vx83-mxcj/GHSA-p5xh-vx83-mxcj.json +++ b/advisories/github-reviewed/2020/03/GHSA-p5xh-vx83-mxcj/GHSA-p5xh-vx83-mxcj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p5xh-vx83-mxcj", - "modified": "2024-11-18T22:24:59Z", + "modified": "2024-11-25T18:33:22Z", "published": "2020-03-31T15:40:12Z", "aliases": [ "CVE-2020-10109" @@ -76,6 +76,14 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2022/02/msg00021.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6ISMZFZBWW4EV6ETJGXAYIXN3AT7GBPL" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YW3NIL7VXSGJND2Q4BSXM3CFTAFU6T7D" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6ISMZFZBWW4EV6ETJGXAYIXN3AT7GBPL" diff --git a/advisories/github-reviewed/2022/02/GHSA-92x2-jw7w-xvvx/GHSA-92x2-jw7w-xvvx.json b/advisories/github-reviewed/2022/02/GHSA-92x2-jw7w-xvvx/GHSA-92x2-jw7w-xvvx.json index 0445bede270..98061a4fc96 100644 --- a/advisories/github-reviewed/2022/02/GHSA-92x2-jw7w-xvvx/GHSA-92x2-jw7w-xvvx.json +++ b/advisories/github-reviewed/2022/02/GHSA-92x2-jw7w-xvvx/GHSA-92x2-jw7w-xvvx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-92x2-jw7w-xvvx", - "modified": "2024-11-18T22:48:32Z", + "modified": "2024-11-25T18:33:22Z", "published": "2022-02-07T22:36:00Z", "aliases": [ "CVE-2022-21712" @@ -68,6 +68,14 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2022/02/msg00021.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7U6KYDTOLPICAVSR34G2WRYLFBD2YW5K" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GLKHA6WREIVAMBQD7KKWYHPHGGNKMAG6" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7U6KYDTOLPICAVSR34G2WRYLFBD2YW5K" diff --git a/advisories/github-reviewed/2022/03/GHSA-rv6r-3f5q-9rgx/GHSA-rv6r-3f5q-9rgx.json b/advisories/github-reviewed/2022/03/GHSA-rv6r-3f5q-9rgx/GHSA-rv6r-3f5q-9rgx.json index 8fc9f992d58..8f0d42b5d15 100644 --- a/advisories/github-reviewed/2022/03/GHSA-rv6r-3f5q-9rgx/GHSA-rv6r-3f5q-9rgx.json +++ b/advisories/github-reviewed/2022/03/GHSA-rv6r-3f5q-9rgx/GHSA-rv6r-3f5q-9rgx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rv6r-3f5q-9rgx", - "modified": "2024-11-18T22:50:32Z", + "modified": "2024-11-25T18:33:22Z", "published": "2022-03-03T19:02:08Z", "aliases": [ "CVE-2022-21716" @@ -72,6 +72,14 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2022/03/msg00009.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7U6KYDTOLPICAVSR34G2WRYLFBD2YW5K" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GLKHA6WREIVAMBQD7KKWYHPHGGNKMAG6" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7U6KYDTOLPICAVSR34G2WRYLFBD2YW5K" diff --git a/advisories/github-reviewed/2022/04/GHSA-c2jg-hw38-jrqq/GHSA-c2jg-hw38-jrqq.json b/advisories/github-reviewed/2022/04/GHSA-c2jg-hw38-jrqq/GHSA-c2jg-hw38-jrqq.json index 7e6b77d7a66..348a6470be7 100644 --- a/advisories/github-reviewed/2022/04/GHSA-c2jg-hw38-jrqq/GHSA-c2jg-hw38-jrqq.json +++ b/advisories/github-reviewed/2022/04/GHSA-c2jg-hw38-jrqq/GHSA-c2jg-hw38-jrqq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c2jg-hw38-jrqq", - "modified": "2024-11-18T22:51:19Z", + "modified": "2024-11-25T18:33:24Z", "published": "2022-04-04T21:29:41Z", "aliases": [ "CVE-2022-24801" @@ -68,6 +68,14 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2022/05/msg00003.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7U6KYDTOLPICAVSR34G2WRYLFBD2YW5K" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GLKHA6WREIVAMBQD7KKWYHPHGGNKMAG6" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7U6KYDTOLPICAVSR34G2WRYLFBD2YW5K" diff --git a/advisories/unreviewed/2022/05/GHSA-73q3-2843-4j2x/GHSA-73q3-2843-4j2x.json b/advisories/unreviewed/2022/05/GHSA-73q3-2843-4j2x/GHSA-73q3-2843-4j2x.json index 13ea1a6f938..30f20867ab0 100644 --- a/advisories/unreviewed/2022/05/GHSA-73q3-2843-4j2x/GHSA-73q3-2843-4j2x.json +++ b/advisories/unreviewed/2022/05/GHSA-73q3-2843-4j2x/GHSA-73q3-2843-4j2x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-73q3-2843-4j2x", - "modified": "2022-10-24T19:00:17Z", + "modified": "2024-11-25T18:33:22Z", "published": "2022-05-24T17:46:32Z", "aliases": [ "CVE-2021-24171" diff --git a/advisories/unreviewed/2023/03/GHSA-pj35-hgmm-7fgg/GHSA-pj35-hgmm-7fgg.json b/advisories/unreviewed/2023/03/GHSA-pj35-hgmm-7fgg/GHSA-pj35-hgmm-7fgg.json index 81730e916bf..8c33adb49d8 100644 --- a/advisories/unreviewed/2023/03/GHSA-pj35-hgmm-7fgg/GHSA-pj35-hgmm-7fgg.json +++ b/advisories/unreviewed/2023/03/GHSA-pj35-hgmm-7fgg/GHSA-pj35-hgmm-7fgg.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-287" + "CWE-287", + "CWE-306" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-46w2-vp86-hhwc/GHSA-46w2-vp86-hhwc.json b/advisories/unreviewed/2024/02/GHSA-46w2-vp86-hhwc/GHSA-46w2-vp86-hhwc.json index 4ba404947a0..71197f7e8e2 100644 --- a/advisories/unreviewed/2024/02/GHSA-46w2-vp86-hhwc/GHSA-46w2-vp86-hhwc.json +++ b/advisories/unreviewed/2024/02/GHSA-46w2-vp86-hhwc/GHSA-46w2-vp86-hhwc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-46w2-vp86-hhwc", - "modified": "2024-02-15T09:30:36Z", + "modified": "2024-11-25T18:33:23Z", "published": "2024-02-15T09:30:35Z", "aliases": [ "CVE-2024-24256" ], "details": "SQL Injection vulnerability in Yonyou space-time enterprise information integration platform v.9.0 and before allows an attacker to obtain sensitive information via the gwbhAIM parameter in the saveMove.jsp in the hr_position directory.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-15T08:15:46Z" diff --git a/advisories/unreviewed/2024/02/GHSA-ww2r-4hmc-9mh3/GHSA-ww2r-4hmc-9mh3.json b/advisories/unreviewed/2024/02/GHSA-ww2r-4hmc-9mh3/GHSA-ww2r-4hmc-9mh3.json index b61ef053e33..48515997036 100644 --- a/advisories/unreviewed/2024/02/GHSA-ww2r-4hmc-9mh3/GHSA-ww2r-4hmc-9mh3.json +++ b/advisories/unreviewed/2024/02/GHSA-ww2r-4hmc-9mh3/GHSA-ww2r-4hmc-9mh3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-ww2r-4hmc-9mh3", - "modified": "2024-02-21T09:31:01Z", + "modified": "2024-11-25T18:33:23Z", "published": "2024-02-21T09:31:01Z", "aliases": [ "CVE-2023-42889" ], "details": "The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.1, macOS Monterey 12.7.1, macOS Ventura 13.6.1. An app may be able to bypass certain Privacy preferences.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-290" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-21T07:15:50Z" diff --git a/advisories/unreviewed/2024/04/GHSA-fpvp-qqmr-38cx/GHSA-fpvp-qqmr-38cx.json b/advisories/unreviewed/2024/04/GHSA-fpvp-qqmr-38cx/GHSA-fpvp-qqmr-38cx.json index 17cef4710d7..2089f403035 100644 --- a/advisories/unreviewed/2024/04/GHSA-fpvp-qqmr-38cx/GHSA-fpvp-qqmr-38cx.json +++ b/advisories/unreviewed/2024/04/GHSA-fpvp-qqmr-38cx/GHSA-fpvp-qqmr-38cx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fpvp-qqmr-38cx", - "modified": "2024-04-05T21:32:42Z", + "modified": "2024-11-25T18:33:23Z", "published": "2024-04-05T21:32:42Z", "aliases": [ "CVE-2024-27231" ], "details": "In tmu_get_tr_stats of tmu.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-05T20:15:07Z" diff --git a/advisories/unreviewed/2024/05/GHSA-35xf-7pfr-g5f5/GHSA-35xf-7pfr-g5f5.json b/advisories/unreviewed/2024/05/GHSA-35xf-7pfr-g5f5/GHSA-35xf-7pfr-g5f5.json index d13d0f06f22..4647204bf6d 100644 --- a/advisories/unreviewed/2024/05/GHSA-35xf-7pfr-g5f5/GHSA-35xf-7pfr-g5f5.json +++ b/advisories/unreviewed/2024/05/GHSA-35xf-7pfr-g5f5/GHSA-35xf-7pfr-g5f5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-35xf-7pfr-g5f5", - "modified": "2024-10-07T12:30:43Z", + "modified": "2024-11-25T18:33:24Z", "published": "2024-05-20T15:31:44Z", "aliases": [ "CVE-2024-27312" diff --git a/advisories/unreviewed/2024/05/GHSA-3vg8-7495-3gjw/GHSA-3vg8-7495-3gjw.json b/advisories/unreviewed/2024/05/GHSA-3vg8-7495-3gjw/GHSA-3vg8-7495-3gjw.json index 92a0b5379cc..773cb68c1af 100644 --- a/advisories/unreviewed/2024/05/GHSA-3vg8-7495-3gjw/GHSA-3vg8-7495-3gjw.json +++ b/advisories/unreviewed/2024/05/GHSA-3vg8-7495-3gjw/GHSA-3vg8-7495-3gjw.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-48w7-3xpj-xq9c/GHSA-48w7-3xpj-xq9c.json b/advisories/unreviewed/2024/05/GHSA-48w7-3xpj-xq9c/GHSA-48w7-3xpj-xq9c.json index 8f53e95a495..4f05ebc9efa 100644 --- a/advisories/unreviewed/2024/05/GHSA-48w7-3xpj-xq9c/GHSA-48w7-3xpj-xq9c.json +++ b/advisories/unreviewed/2024/05/GHSA-48w7-3xpj-xq9c/GHSA-48w7-3xpj-xq9c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-48w7-3xpj-xq9c", - "modified": "2024-05-14T15:32:54Z", + "modified": "2024-11-25T18:33:24Z", "published": "2024-05-14T15:32:54Z", "aliases": [ "CVE-2024-29166" ], "details": "HDF5 through 1.14.3 contains a buffer overflow in H5O__linfo_decode, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:15:33Z" diff --git a/advisories/unreviewed/2024/05/GHSA-542w-wwr4-wgph/GHSA-542w-wwr4-wgph.json b/advisories/unreviewed/2024/05/GHSA-542w-wwr4-wgph/GHSA-542w-wwr4-wgph.json index 877d28be74b..8da6732322e 100644 --- a/advisories/unreviewed/2024/05/GHSA-542w-wwr4-wgph/GHSA-542w-wwr4-wgph.json +++ b/advisories/unreviewed/2024/05/GHSA-542w-wwr4-wgph/GHSA-542w-wwr4-wgph.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-99hg-9w72-jwwc/GHSA-99hg-9w72-jwwc.json b/advisories/unreviewed/2024/05/GHSA-99hg-9w72-jwwc/GHSA-99hg-9w72-jwwc.json index bcda298e3e2..bfc16731ea1 100644 --- a/advisories/unreviewed/2024/05/GHSA-99hg-9w72-jwwc/GHSA-99hg-9w72-jwwc.json +++ b/advisories/unreviewed/2024/05/GHSA-99hg-9w72-jwwc/GHSA-99hg-9w72-jwwc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-99hg-9w72-jwwc", - "modified": "2024-05-14T18:30:48Z", + "modified": "2024-11-25T18:33:24Z", "published": "2024-05-14T18:30:48Z", "aliases": [ "CVE-2024-33876" ], "details": "HDF5 Library through 1.14.3 has a heap buffer overflow in H5S__point_deserialize in H5Spoint.c.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:38:10Z" diff --git a/advisories/unreviewed/2024/05/GHSA-cw65-c3g7-7rw3/GHSA-cw65-c3g7-7rw3.json b/advisories/unreviewed/2024/05/GHSA-cw65-c3g7-7rw3/GHSA-cw65-c3g7-7rw3.json index 3071b9a69d6..3e52b53c546 100644 --- a/advisories/unreviewed/2024/05/GHSA-cw65-c3g7-7rw3/GHSA-cw65-c3g7-7rw3.json +++ b/advisories/unreviewed/2024/05/GHSA-cw65-c3g7-7rw3/GHSA-cw65-c3g7-7rw3.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-259" + "CWE-259", + "CWE-798" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-gg2x-v7xp-pj7x/GHSA-gg2x-v7xp-pj7x.json b/advisories/unreviewed/2024/05/GHSA-gg2x-v7xp-pj7x/GHSA-gg2x-v7xp-pj7x.json index b8165c88370..993cd2193bd 100644 --- a/advisories/unreviewed/2024/05/GHSA-gg2x-v7xp-pj7x/GHSA-gg2x-v7xp-pj7x.json +++ b/advisories/unreviewed/2024/05/GHSA-gg2x-v7xp-pj7x/GHSA-gg2x-v7xp-pj7x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gg2x-v7xp-pj7x", - "modified": "2024-05-03T15:30:54Z", + "modified": "2024-11-25T18:33:24Z", "published": "2024-05-03T15:30:54Z", "aliases": [ "CVE-2023-6363" ], "details": "Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to make improper GPU memory processing operations. If the system’s memory is carefully prepared by the user, then this in turn could give them access to already freed memory.\nThis issue affects Valhall GPU Kernel Driver: from r41p0 through r47p0; Arm 5th Gen GPU Architecture Kernel Driver: from r41p0 through r47p0.\n\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-416" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-03T14:15:10Z" diff --git a/advisories/unreviewed/2024/05/GHSA-gvjh-r2g7-mjgx/GHSA-gvjh-r2g7-mjgx.json b/advisories/unreviewed/2024/05/GHSA-gvjh-r2g7-mjgx/GHSA-gvjh-r2g7-mjgx.json index ccade6497ec..95a4894fd81 100644 --- a/advisories/unreviewed/2024/05/GHSA-gvjh-r2g7-mjgx/GHSA-gvjh-r2g7-mjgx.json +++ b/advisories/unreviewed/2024/05/GHSA-gvjh-r2g7-mjgx/GHSA-gvjh-r2g7-mjgx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gvjh-r2g7-mjgx", - "modified": "2024-05-07T21:31:46Z", + "modified": "2024-11-25T18:33:24Z", "published": "2024-05-07T21:31:46Z", "aliases": [ "CVE-2024-0022" ], "details": "In multiple functions of CompanionDeviceManagerService.java, there is a possible launch NotificationAccessConfirmationActivity of another user profile due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-07T21:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-m65c-w77g-m7jv/GHSA-m65c-w77g-m7jv.json b/advisories/unreviewed/2024/05/GHSA-m65c-w77g-m7jv/GHSA-m65c-w77g-m7jv.json index dbb0e560ced..224197979c4 100644 --- a/advisories/unreviewed/2024/05/GHSA-m65c-w77g-m7jv/GHSA-m65c-w77g-m7jv.json +++ b/advisories/unreviewed/2024/05/GHSA-m65c-w77g-m7jv/GHSA-m65c-w77g-m7jv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m65c-w77g-m7jv", - "modified": "2024-05-03T18:30:37Z", + "modified": "2024-11-25T18:33:24Z", "published": "2024-05-03T18:30:37Z", "aliases": [ "CVE-2024-30851" ], "details": "Directory Traversal vulnerability in codesiddhant Jasmin Ransomware v.1.0.1 allows an attacker to obtain sensitive information via the download_file.php component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-03T17:15:07Z" diff --git a/advisories/unreviewed/2024/05/GHSA-p33w-frg4-vqgm/GHSA-p33w-frg4-vqgm.json b/advisories/unreviewed/2024/05/GHSA-p33w-frg4-vqgm/GHSA-p33w-frg4-vqgm.json index 06164130897..501a60a7d70 100644 --- a/advisories/unreviewed/2024/05/GHSA-p33w-frg4-vqgm/GHSA-p33w-frg4-vqgm.json +++ b/advisories/unreviewed/2024/05/GHSA-p33w-frg4-vqgm/GHSA-p33w-frg4-vqgm.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-wcjg-965f-9jwr/GHSA-wcjg-965f-9jwr.json b/advisories/unreviewed/2024/05/GHSA-wcjg-965f-9jwr/GHSA-wcjg-965f-9jwr.json index e0c263c3966..a4b95a3a306 100644 --- a/advisories/unreviewed/2024/05/GHSA-wcjg-965f-9jwr/GHSA-wcjg-965f-9jwr.json +++ b/advisories/unreviewed/2024/05/GHSA-wcjg-965f-9jwr/GHSA-wcjg-965f-9jwr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wcjg-965f-9jwr", - "modified": "2024-05-18T21:30:34Z", + "modified": "2024-11-25T18:33:25Z", "published": "2024-05-18T21:30:34Z", "aliases": [ "CVE-2024-36043" ], "details": "question_image.ts in SurveyJS Form Library before 1.10.4 allows contentMode=youtube XSS via the imageLink property.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-18T20:15:15Z" diff --git a/advisories/unreviewed/2024/05/GHSA-wv9p-mpx3-mvr5/GHSA-wv9p-mpx3-mvr5.json b/advisories/unreviewed/2024/05/GHSA-wv9p-mpx3-mvr5/GHSA-wv9p-mpx3-mvr5.json index 63d656695eb..c3565f909f0 100644 --- a/advisories/unreviewed/2024/05/GHSA-wv9p-mpx3-mvr5/GHSA-wv9p-mpx3-mvr5.json +++ b/advisories/unreviewed/2024/05/GHSA-wv9p-mpx3-mvr5/GHSA-wv9p-mpx3-mvr5.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-x283-qfw9-8vwr/GHSA-x283-qfw9-8vwr.json b/advisories/unreviewed/2024/05/GHSA-x283-qfw9-8vwr/GHSA-x283-qfw9-8vwr.json index 2db4b1db3ef..80317796612 100644 --- a/advisories/unreviewed/2024/05/GHSA-x283-qfw9-8vwr/GHSA-x283-qfw9-8vwr.json +++ b/advisories/unreviewed/2024/05/GHSA-x283-qfw9-8vwr/GHSA-x283-qfw9-8vwr.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-463r-p989-2f9j/GHSA-463r-p989-2f9j.json b/advisories/unreviewed/2024/07/GHSA-463r-p989-2f9j/GHSA-463r-p989-2f9j.json index 8498acec3ac..011bb67840c 100644 --- a/advisories/unreviewed/2024/07/GHSA-463r-p989-2f9j/GHSA-463r-p989-2f9j.json +++ b/advisories/unreviewed/2024/07/GHSA-463r-p989-2f9j/GHSA-463r-p989-2f9j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-463r-p989-2f9j", - "modified": "2024-07-12T15:31:25Z", + "modified": "2024-11-25T18:33:24Z", "published": "2024-07-01T21:31:13Z", "aliases": [ "CVE-2024-36387" ], "details": "Serving WebSocket protocol upgrades over a HTTP/2 connection could result in a Null Pointer dereference, leading to a crash of the server process, degrading performance.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } ], "affected": [ @@ -25,13 +28,17 @@ { "type": "WEB", "url": "https://security.netapp.com/advisory/ntap-20240712-0001" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/07/01/4" } ], "database_specific": { "cwe_ids": [ "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-01T19:15:03Z" diff --git a/advisories/unreviewed/2024/07/GHSA-c6gx-2rc7-2pg3/GHSA-c6gx-2rc7-2pg3.json b/advisories/unreviewed/2024/07/GHSA-c6gx-2rc7-2pg3/GHSA-c6gx-2rc7-2pg3.json index fd961dcb5d7..2a27a094692 100644 --- a/advisories/unreviewed/2024/07/GHSA-c6gx-2rc7-2pg3/GHSA-c6gx-2rc7-2pg3.json +++ b/advisories/unreviewed/2024/07/GHSA-c6gx-2rc7-2pg3/GHSA-c6gx-2rc7-2pg3.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-78", "CWE-94" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/07/GHSA-hj82-9w85-vjh7/GHSA-hj82-9w85-vjh7.json b/advisories/unreviewed/2024/07/GHSA-hj82-9w85-vjh7/GHSA-hj82-9w85-vjh7.json index b5b1b8454b3..bc751eb6bc2 100644 --- a/advisories/unreviewed/2024/07/GHSA-hj82-9w85-vjh7/GHSA-hj82-9w85-vjh7.json +++ b/advisories/unreviewed/2024/07/GHSA-hj82-9w85-vjh7/GHSA-hj82-9w85-vjh7.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-4m4w-x26h-2qjx/GHSA-4m4w-x26h-2qjx.json b/advisories/unreviewed/2024/08/GHSA-4m4w-x26h-2qjx/GHSA-4m4w-x26h-2qjx.json index ab6b4c50edc..c4978249c7a 100644 --- a/advisories/unreviewed/2024/08/GHSA-4m4w-x26h-2qjx/GHSA-4m4w-x26h-2qjx.json +++ b/advisories/unreviewed/2024/08/GHSA-4m4w-x26h-2qjx/GHSA-4m4w-x26h-2qjx.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-843" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-w7hj-m8mm-jwmh/GHSA-w7hj-m8mm-jwmh.json b/advisories/unreviewed/2024/09/GHSA-w7hj-m8mm-jwmh/GHSA-w7hj-m8mm-jwmh.json index b3d7b71df64..39c7be8337e 100644 --- a/advisories/unreviewed/2024/09/GHSA-w7hj-m8mm-jwmh/GHSA-w7hj-m8mm-jwmh.json +++ b/advisories/unreviewed/2024/09/GHSA-w7hj-m8mm-jwmh/GHSA-w7hj-m8mm-jwmh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w7hj-m8mm-jwmh", - "modified": "2024-09-11T18:31:08Z", + "modified": "2024-11-25T18:33:25Z", "published": "2024-09-11T18:31:08Z", "aliases": [ "CVE-2024-44575" ], "details": "RELY-PCIe v22.2.1 to v23.1.0 does not set the Secure attribute for sensitive cookies in HTTPS sessions, which could cause the user agent to send those cookies in cleartext over an HTTP session.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-732" ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-11T17:15:13Z" diff --git a/advisories/unreviewed/2024/10/GHSA-3c76-p447-jmg2/GHSA-3c76-p447-jmg2.json b/advisories/unreviewed/2024/10/GHSA-3c76-p447-jmg2/GHSA-3c76-p447-jmg2.json index f2792f74fda..c5b2138108c 100644 --- a/advisories/unreviewed/2024/10/GHSA-3c76-p447-jmg2/GHSA-3c76-p447-jmg2.json +++ b/advisories/unreviewed/2024/10/GHSA-3c76-p447-jmg2/GHSA-3c76-p447-jmg2.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-922" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-5x39-cc3p-mj36/GHSA-5x39-cc3p-mj36.json b/advisories/unreviewed/2024/10/GHSA-5x39-cc3p-mj36/GHSA-5x39-cc3p-mj36.json index 520a065d9f6..e1f99cf0635 100644 --- a/advisories/unreviewed/2024/10/GHSA-5x39-cc3p-mj36/GHSA-5x39-cc3p-mj36.json +++ b/advisories/unreviewed/2024/10/GHSA-5x39-cc3p-mj36/GHSA-5x39-cc3p-mj36.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-538" + "CWE-538", + "CWE-862" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-f9c2-396j-6x9r/GHSA-f9c2-396j-6x9r.json b/advisories/unreviewed/2024/10/GHSA-f9c2-396j-6x9r/GHSA-f9c2-396j-6x9r.json index f20e01bcf5d..9b680c03df6 100644 --- a/advisories/unreviewed/2024/10/GHSA-f9c2-396j-6x9r/GHSA-f9c2-396j-6x9r.json +++ b/advisories/unreviewed/2024/10/GHSA-f9c2-396j-6x9r/GHSA-f9c2-396j-6x9r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f9c2-396j-6x9r", - "modified": "2024-10-03T18:30:36Z", + "modified": "2024-11-25T18:33:25Z", "published": "2024-10-03T18:30:36Z", "aliases": [ "CVE-2024-34535" ], "details": "In Mastodon 4.1.6, API endpoint rate limiting can be bypassed by setting a crafted HTTP request header.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-444" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-03T18:15:04Z" diff --git a/advisories/unreviewed/2024/11/GHSA-23ff-wfv3-xrvg/GHSA-23ff-wfv3-xrvg.json b/advisories/unreviewed/2024/11/GHSA-23ff-wfv3-xrvg/GHSA-23ff-wfv3-xrvg.json new file mode 100644 index 00000000000..c90b9b511fa --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-23ff-wfv3-xrvg/GHSA-23ff-wfv3-xrvg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-23ff-wfv3-xrvg", + "modified": "2024-11-25T18:33:27Z", + "published": "2024-11-25T18:33:27Z", + "aliases": [ + "CVE-2024-11498" + ], + "details": "There exists a stack buffer overflow in libjxl. A specifically-crafted file can cause the JPEG XL decoder to use large amounts of stack space (up to 256mb is possible, maybe 512mb), potentially exhausting the stack. An attacker can craft a file that will cause excessive memory usage. We recommend upgrading past commit 65fbec56bc578b6b6ee02a527be70787bbd053b0.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11498" + }, + { + "type": "WEB", + "url": "https://github.com/libjxl/libjxl/pull/3943" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-25T14:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-27mx-5g65-22g6/GHSA-27mx-5g65-22g6.json b/advisories/unreviewed/2024/11/GHSA-27mx-5g65-22g6/GHSA-27mx-5g65-22g6.json new file mode 100644 index 00000000000..e9d5ac4cba1 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-27mx-5g65-22g6/GHSA-27mx-5g65-22g6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-27mx-5g65-22g6", + "modified": "2024-11-25T18:33:26Z", + "published": "2024-11-25T18:33:26Z", + "aliases": [ + "CVE-2024-11670" + ], + "details": "Incorrect authorization in the permission validation component of Devolutions Remote Desktop Manager 2024.2.21 and earlier on Windows allows a malicious authenticated user to bypass the \"View Password\" permission via specific actions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11670" + }, + { + "type": "WEB", + "url": "https://devolutions.net/security/advisories/DEVO-2024-0015" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-25T15:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-2q9p-p4h4-mqv8/GHSA-2q9p-p4h4-mqv8.json b/advisories/unreviewed/2024/11/GHSA-2q9p-p4h4-mqv8/GHSA-2q9p-p4h4-mqv8.json new file mode 100644 index 00000000000..2c33d3a7be3 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-2q9p-p4h4-mqv8/GHSA-2q9p-p4h4-mqv8.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2q9p-p4h4-mqv8", + "modified": "2024-11-25T18:33:26Z", + "published": "2024-11-25T18:33:26Z", + "aliases": [ + "CVE-2024-11649" + ], + "details": "A vulnerability has been found in 1000 Projects Beauty Parlour Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/search-appointment.php. The manipulation of the argument searchdata leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11649" + }, + { + "type": "WEB", + "url": "https://github.com/zgaz/CVE/issues/1" + }, + { + "type": "WEB", + "url": "https://1000projects.org" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.285970" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.285970" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.451245" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74", + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-25T02:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-3864-rp2m-2qfj/GHSA-3864-rp2m-2qfj.json b/advisories/unreviewed/2024/11/GHSA-3864-rp2m-2qfj/GHSA-3864-rp2m-2qfj.json new file mode 100644 index 00000000000..c04663d7085 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-3864-rp2m-2qfj/GHSA-3864-rp2m-2qfj.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3864-rp2m-2qfj", + "modified": "2024-11-25T18:33:26Z", + "published": "2024-11-25T18:33:26Z", + "aliases": [ + "CVE-2024-52787" + ], + "details": "An issue in the upload_documents method of libre-chat v0.0.6 allows attackers to execute a path traversal via supplying a crafted filename in an uploaded file.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52787" + }, + { + "type": "WEB", + "url": "https://github.com/vemonet/libre-chat/issues/10" + }, + { + "type": "WEB", + "url": "https://github.com/vemonet/libre-chat/pull/9" + }, + { + "type": "WEB", + "url": "https://github.com/vemonet/libre-chat/commit/dbb8e3400e5258112179783d74c9cc54310cb72b" + }, + { + "type": "WEB", + "url": "https://gist.github.com/jxfzzzt/276a6e8cfbc54d2c2711bb51d8d3dff3" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-25T18:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-3h38-466h-xfcc/GHSA-3h38-466h-xfcc.json b/advisories/unreviewed/2024/11/GHSA-3h38-466h-xfcc/GHSA-3h38-466h-xfcc.json index 46d8a46c94f..f495a3e6e10 100644 --- a/advisories/unreviewed/2024/11/GHSA-3h38-466h-xfcc/GHSA-3h38-466h-xfcc.json +++ b/advisories/unreviewed/2024/11/GHSA-3h38-466h-xfcc/GHSA-3h38-466h-xfcc.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-439g-ccc3-vp4h/GHSA-439g-ccc3-vp4h.json b/advisories/unreviewed/2024/11/GHSA-439g-ccc3-vp4h/GHSA-439g-ccc3-vp4h.json index 0f820f5131b..148c62e2d28 100644 --- a/advisories/unreviewed/2024/11/GHSA-439g-ccc3-vp4h/GHSA-439g-ccc3-vp4h.json +++ b/advisories/unreviewed/2024/11/GHSA-439g-ccc3-vp4h/GHSA-439g-ccc3-vp4h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-439g-ccc3-vp4h", - "modified": "2024-11-25T06:34:58Z", + "modified": "2024-11-25T18:33:26Z", "published": "2024-11-25T06:34:58Z", "aliases": [ "CVE-2024-10710" ], "details": "The YaDisk Files WordPress plugin through 1.2.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-25T06:15:05Z" diff --git a/advisories/unreviewed/2024/11/GHSA-4j83-7cvp-5r59/GHSA-4j83-7cvp-5r59.json b/advisories/unreviewed/2024/11/GHSA-4j83-7cvp-5r59/GHSA-4j83-7cvp-5r59.json new file mode 100644 index 00000000000..762673bcbb0 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-4j83-7cvp-5r59/GHSA-4j83-7cvp-5r59.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4j83-7cvp-5r59", + "modified": "2024-11-25T18:33:26Z", + "published": "2024-11-25T18:33:26Z", + "aliases": [ + "CVE-2024-8272" + ], + "details": "The com.uaudio.bsd.helper service, responsible for handling privileged operations, fails to implement critical client validation during XPC inter-process communication (IPC). Specifically, the service does not verify the code requirements, entitlements, or security flags of any client attempting to establish a connection. This lack of proper validation allows unauthorized clients to exploit the service's methods and escalate privileges to root.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8272" + }, + { + "type": "WEB", + "url": "https://pentraze.com/vulnerability-reports" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-25T18:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-5pp5-4vfv-784q/GHSA-5pp5-4vfv-784q.json b/advisories/unreviewed/2024/11/GHSA-5pp5-4vfv-784q/GHSA-5pp5-4vfv-784q.json new file mode 100644 index 00000000000..dbf79dbbe7e --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-5pp5-4vfv-784q/GHSA-5pp5-4vfv-784q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5pp5-4vfv-784q", + "modified": "2024-11-25T18:33:26Z", + "published": "2024-11-25T18:33:26Z", + "aliases": [ + "CVE-2024-11403" + ], + "details": "There exists an out of bounds read/write in LibJXL versions prior to commit 9cc451b91b74ba470fd72bd48c121e9f33d24c99. The JPEG decoder used by the JPEG XL encoder when doing JPEG recompression (i.e. if using JxlEncoderAddJPEGFrame on untrusted input) does not properly check bounds in the presence of incomplete codes. This could lead to an out-of-bounds write. In jpegli which is released as part of the same project, the same vulnerability is present. However, the relevant buffer is part of a bigger structure, and the code makes no assumptions on the values that could be overwritten. The issue could however cause jpegli to read uninitialised memory, or addresses of functions.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:P/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11403" + }, + { + "type": "WEB", + "url": "https://github.com/libjxl/libjxl/commit/9cc451b91b74ba470fd72bd48c121e9f33d24c99" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-25T14:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-5wp7-h4j5-xf39/GHSA-5wp7-h4j5-xf39.json b/advisories/unreviewed/2024/11/GHSA-5wp7-h4j5-xf39/GHSA-5wp7-h4j5-xf39.json new file mode 100644 index 00000000000..a3b8df417c7 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-5wp7-h4j5-xf39/GHSA-5wp7-h4j5-xf39.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5wp7-h4j5-xf39", + "modified": "2024-11-25T18:33:26Z", + "published": "2024-11-25T18:33:26Z", + "aliases": [ + "CVE-2024-11647" + ], + "details": "A vulnerability, which was classified as critical, has been found in 1000 Projects Beauty Parlour Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/view-appointment.php. The manipulation of the argument viewid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11647" + }, + { + "type": "WEB", + "url": "https://github.com/ppp-src/CVE/issues/34" + }, + { + "type": "WEB", + "url": "https://1000projects.org" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.285968" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.285968" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.446576" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74", + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-25T01:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-6f9c-q4ff-c85g/GHSA-6f9c-q4ff-c85g.json b/advisories/unreviewed/2024/11/GHSA-6f9c-q4ff-c85g/GHSA-6f9c-q4ff-c85g.json index b8d7ea00878..1b4698031fa 100644 --- a/advisories/unreviewed/2024/11/GHSA-6f9c-q4ff-c85g/GHSA-6f9c-q4ff-c85g.json +++ b/advisories/unreviewed/2024/11/GHSA-6f9c-q4ff-c85g/GHSA-6f9c-q4ff-c85g.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-404" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-6hr3-3gcm-jjw8/GHSA-6hr3-3gcm-jjw8.json b/advisories/unreviewed/2024/11/GHSA-6hr3-3gcm-jjw8/GHSA-6hr3-3gcm-jjw8.json new file mode 100644 index 00000000000..59381545b0c --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-6hr3-3gcm-jjw8/GHSA-6hr3-3gcm-jjw8.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6hr3-3gcm-jjw8", + "modified": "2024-11-25T18:33:26Z", + "published": "2024-11-25T18:33:26Z", + "aliases": [ + "CVE-2024-45756" + ], + "details": "An issue was discovered in Centreon centreon-open-tickets 24.10.x before 24.10.0, 24.04.x before 24.04.2, 23.10.x before 23.10.1, 23.04.x before 23.04.3, and 22.10.x before 22.10.2. SQL injection can occur in the form to create a ticket. Exploitation is only accessible to authenticated users with high-privileged access.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45756" + }, + { + "type": "WEB", + "url": "https://github.com/centreon/centreon/release" + }, + { + "type": "WEB", + "url": "https://thewatch.centreon.com/latest-security-bulletins-64/cve-2024-45756-centreon-open-tickets-high-severity-4064" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-25T18:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-6qqc-x73q-pqcm/GHSA-6qqc-x73q-pqcm.json b/advisories/unreviewed/2024/11/GHSA-6qqc-x73q-pqcm/GHSA-6qqc-x73q-pqcm.json index 4f040784aba..e778a83117d 100644 --- a/advisories/unreviewed/2024/11/GHSA-6qqc-x73q-pqcm/GHSA-6qqc-x73q-pqcm.json +++ b/advisories/unreviewed/2024/11/GHSA-6qqc-x73q-pqcm/GHSA-6qqc-x73q-pqcm.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-7866-w9g3-g699/GHSA-7866-w9g3-g699.json b/advisories/unreviewed/2024/11/GHSA-7866-w9g3-g699/GHSA-7866-w9g3-g699.json index d4c66f6ceba..cc50aa9c977 100644 --- a/advisories/unreviewed/2024/11/GHSA-7866-w9g3-g699/GHSA-7866-w9g3-g699.json +++ b/advisories/unreviewed/2024/11/GHSA-7866-w9g3-g699/GHSA-7866-w9g3-g699.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7866-w9g3-g699", - "modified": "2024-11-19T18:31:07Z", + "modified": "2024-11-25T18:33:25Z", "published": "2024-11-19T18:31:07Z", "aliases": [ "CVE-2024-53075" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nriscv: Prevent a bad reference count on CPU nodes\n\nWhen populating cache leaves we previously fetched the CPU device node\nat the very beginning. But when ACPI is enabled we go through a\nspecific branch which returns early and does not call 'of_node_put' for\nthe node that was acquired.\n\nSince we are not using a CPU device node for the ACPI code anyways, we\ncan simply move the initialization of it just passed the ACPI block, and\nwe are guaranteed to have an 'of_node_put' call for the acquired node.\nThis prevents a bad reference count of the CPU device node.\n\nMoreover, the previous function did not check for errors when acquiring\nthe device node, so a return -ENOENT has been added for that case.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-19T18:15:27Z" diff --git a/advisories/unreviewed/2024/11/GHSA-7ghh-hpqx-6wf8/GHSA-7ghh-hpqx-6wf8.json b/advisories/unreviewed/2024/11/GHSA-7ghh-hpqx-6wf8/GHSA-7ghh-hpqx-6wf8.json index 2967f9449a6..ba0410666b0 100644 --- a/advisories/unreviewed/2024/11/GHSA-7ghh-hpqx-6wf8/GHSA-7ghh-hpqx-6wf8.json +++ b/advisories/unreviewed/2024/11/GHSA-7ghh-hpqx-6wf8/GHSA-7ghh-hpqx-6wf8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7ghh-hpqx-6wf8", - "modified": "2024-11-19T18:31:07Z", + "modified": "2024-11-25T18:33:25Z", "published": "2024-11-19T18:31:07Z", "aliases": [ "CVE-2024-53074" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: iwlwifi: mvm: don't leak a link on AP removal\n\nRelease the link mapping resource in AP removal. This impacted devices\nthat do not support the MLD API (9260 and down).\nOn those devices, we couldn't start the AP again after the AP has been\nalready started and stopped.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-772" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-19T18:15:27Z" diff --git a/advisories/unreviewed/2024/11/GHSA-7qpw-jhj9-8g8x/GHSA-7qpw-jhj9-8g8x.json b/advisories/unreviewed/2024/11/GHSA-7qpw-jhj9-8g8x/GHSA-7qpw-jhj9-8g8x.json new file mode 100644 index 00000000000..d7b72614373 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-7qpw-jhj9-8g8x/GHSA-7qpw-jhj9-8g8x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7qpw-jhj9-8g8x", + "modified": "2024-11-25T18:33:27Z", + "published": "2024-11-25T18:33:26Z", + "aliases": [ + "CVE-2024-11672" + ], + "details": "Incorrect authorization in the add permission component in Devolutions Remote Desktop Manager 2024.2.21 and earlier on Windows allows an authenticated malicious user to bypass the \"Add\" permission via the import in vault feature.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11672" + }, + { + "type": "WEB", + "url": "https://devolutions.net/security/advisories/DEVO-2024-0016" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-25T15:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-8cr3-2g2w-j5m2/GHSA-8cr3-2g2w-j5m2.json b/advisories/unreviewed/2024/11/GHSA-8cr3-2g2w-j5m2/GHSA-8cr3-2g2w-j5m2.json index a42115d4eb0..0cc8857f679 100644 --- a/advisories/unreviewed/2024/11/GHSA-8cr3-2g2w-j5m2/GHSA-8cr3-2g2w-j5m2.json +++ b/advisories/unreviewed/2024/11/GHSA-8cr3-2g2w-j5m2/GHSA-8cr3-2g2w-j5m2.json @@ -48,7 +48,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-8pvr-h3wm-pfpm/GHSA-8pvr-h3wm-pfpm.json b/advisories/unreviewed/2024/11/GHSA-8pvr-h3wm-pfpm/GHSA-8pvr-h3wm-pfpm.json index 3a2c1b12f87..cb8775bc121 100644 --- a/advisories/unreviewed/2024/11/GHSA-8pvr-h3wm-pfpm/GHSA-8pvr-h3wm-pfpm.json +++ b/advisories/unreviewed/2024/11/GHSA-8pvr-h3wm-pfpm/GHSA-8pvr-h3wm-pfpm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8pvr-h3wm-pfpm", - "modified": "2024-11-25T06:34:59Z", + "modified": "2024-11-25T18:33:26Z", "published": "2024-11-25T06:34:59Z", "aliases": [ "CVE-2024-7056" ], "details": "The WPForms WordPress plugin before 1.9.1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as Admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-25T06:15:07Z" diff --git a/advisories/unreviewed/2024/11/GHSA-9r3x-3x49-29r7/GHSA-9r3x-3x49-29r7.json b/advisories/unreviewed/2024/11/GHSA-9r3x-3x49-29r7/GHSA-9r3x-3x49-29r7.json index 3ce75a3d98e..cb840cb666b 100644 --- a/advisories/unreviewed/2024/11/GHSA-9r3x-3x49-29r7/GHSA-9r3x-3x49-29r7.json +++ b/advisories/unreviewed/2024/11/GHSA-9r3x-3x49-29r7/GHSA-9r3x-3x49-29r7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9r3x-3x49-29r7", - "modified": "2024-11-19T18:31:07Z", + "modified": "2024-11-25T18:33:25Z", "published": "2024-11-19T18:31:07Z", "aliases": [ "CVE-2024-53068" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware: arm_scmi: Fix slab-use-after-free in scmi_bus_notifier()\n\nThe scmi_dev->name is released prematurely in __scmi_device_destroy(),\nwhich causes slab-use-after-free when accessing scmi_dev->name in\nscmi_bus_notifier(). So move the release of scmi_dev->name to\nscmi_device_release() to avoid slab-use-after-free.\n\n | BUG: KASAN: slab-use-after-free in strncmp+0xe4/0xec\n | Read of size 1 at addr ffffff80a482bcc0 by task swapper/0/1\n |\n | CPU: 1 PID: 1 Comm: swapper/0 Not tainted 6.6.38-debug #1\n | Hardware name: Qualcomm Technologies, Inc. SA8775P Ride (DT)\n | Call trace:\n | dump_backtrace+0x94/0x114\n | show_stack+0x18/0x24\n | dump_stack_lvl+0x48/0x60\n | print_report+0xf4/0x5b0\n | kasan_report+0xa4/0xec\n | __asan_report_load1_noabort+0x20/0x2c\n | strncmp+0xe4/0xec\n | scmi_bus_notifier+0x5c/0x54c\n | notifier_call_chain+0xb4/0x31c\n | blocking_notifier_call_chain+0x68/0x9c\n | bus_notify+0x54/0x78\n | device_del+0x1bc/0x840\n | device_unregister+0x20/0xb4\n | __scmi_device_destroy+0xac/0x280\n | scmi_device_destroy+0x94/0xd0\n | scmi_chan_setup+0x524/0x750\n | scmi_probe+0x7fc/0x1508\n | platform_probe+0xc4/0x19c\n | really_probe+0x32c/0x99c\n | __driver_probe_device+0x15c/0x3c4\n | driver_probe_device+0x5c/0x170\n | __driver_attach+0x1c8/0x440\n | bus_for_each_dev+0xf4/0x178\n | driver_attach+0x3c/0x58\n | bus_add_driver+0x234/0x4d4\n | driver_register+0xf4/0x3c0\n | __platform_driver_register+0x60/0x88\n | scmi_driver_init+0xb0/0x104\n | do_one_initcall+0xb4/0x664\n | kernel_init_freeable+0x3c8/0x894\n | kernel_init+0x24/0x1e8\n | ret_from_fork+0x10/0x20\n |\n | Allocated by task 1:\n | kasan_save_stack+0x2c/0x54\n | kasan_set_track+0x2c/0x40\n | kasan_save_alloc_info+0x24/0x34\n | __kasan_kmalloc+0xa0/0xb8\n | __kmalloc_node_track_caller+0x6c/0x104\n | kstrdup+0x48/0x84\n | kstrdup_const+0x34/0x40\n | __scmi_device_create.part.0+0x8c/0x408\n | scmi_device_create+0x104/0x370\n | scmi_chan_setup+0x2a0/0x750\n | scmi_probe+0x7fc/0x1508\n | platform_probe+0xc4/0x19c\n | really_probe+0x32c/0x99c\n | __driver_probe_device+0x15c/0x3c4\n | driver_probe_device+0x5c/0x170\n | __driver_attach+0x1c8/0x440\n | bus_for_each_dev+0xf4/0x178\n | driver_attach+0x3c/0x58\n | bus_add_driver+0x234/0x4d4\n | driver_register+0xf4/0x3c0\n | __platform_driver_register+0x60/0x88\n | scmi_driver_init+0xb0/0x104\n | do_one_initcall+0xb4/0x664\n | kernel_init_freeable+0x3c8/0x894\n | kernel_init+0x24/0x1e8\n | ret_from_fork+0x10/0x20\n |\n | Freed by task 1:\n | kasan_save_stack+0x2c/0x54\n | kasan_set_track+0x2c/0x40\n | kasan_save_free_info+0x38/0x5c\n | __kasan_slab_free+0xe8/0x164\n | __kmem_cache_free+0x11c/0x230\n | kfree+0x70/0x130\n | kfree_const+0x20/0x40\n | __scmi_device_destroy+0x70/0x280\n | scmi_device_destroy+0x94/0xd0\n | scmi_chan_setup+0x524/0x750\n | scmi_probe+0x7fc/0x1508\n | platform_probe+0xc4/0x19c\n | really_probe+0x32c/0x99c\n | __driver_probe_device+0x15c/0x3c4\n | driver_probe_device+0x5c/0x170\n | __driver_attach+0x1c8/0x440\n | bus_for_each_dev+0xf4/0x178\n | driver_attach+0x3c/0x58\n | bus_add_driver+0x234/0x4d4\n | driver_register+0xf4/0x3c0\n | __platform_driver_register+0x60/0x88\n | scmi_driver_init+0xb0/0x104\n | do_one_initcall+0xb4/0x664\n | kernel_init_freeable+0x3c8/0x894\n | kernel_init+0x24/0x1e8\n | ret_from_fork+0x10/0x20", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-19T18:15:26Z" diff --git a/advisories/unreviewed/2024/11/GHSA-9w8f-6h5p-xj5x/GHSA-9w8f-6h5p-xj5x.json b/advisories/unreviewed/2024/11/GHSA-9w8f-6h5p-xj5x/GHSA-9w8f-6h5p-xj5x.json index b2998fdec4d..621f5bd1444 100644 --- a/advisories/unreviewed/2024/11/GHSA-9w8f-6h5p-xj5x/GHSA-9w8f-6h5p-xj5x.json +++ b/advisories/unreviewed/2024/11/GHSA-9w8f-6h5p-xj5x/GHSA-9w8f-6h5p-xj5x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9w8f-6h5p-xj5x", - "modified": "2024-11-19T18:31:07Z", + "modified": "2024-11-25T18:33:25Z", "published": "2024-11-19T18:31:07Z", "aliases": [ "CVE-2024-53088" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ni40e: fix race condition by adding filter's intermediate sync state\n\nFix a race condition in the i40e driver that leads to MAC/VLAN filters\nbecoming corrupted and leaking. Address the issue that occurs under\nheavy load when multiple threads are concurrently modifying MAC/VLAN\nfilters by setting mac and port VLAN.\n\n1. Thread T0 allocates a filter in i40e_add_filter() within\n i40e_ndo_set_vf_port_vlan().\n2. Thread T1 concurrently frees the filter in __i40e_del_filter() within\n i40e_ndo_set_vf_mac().\n3. Subsequently, i40e_service_task() calls i40e_sync_vsi_filters(), which\n refers to the already freed filter memory, causing corruption.\n\nReproduction steps:\n1. Spawn multiple VFs.\n2. Apply a concurrent heavy load by running parallel operations to change\n MAC addresses on the VFs and change port VLANs on the host.\n3. Observe errors in dmesg:\n\"Error I40E_AQ_RC_ENOSPC adding RX filters on VF XX,\n\tplease set promiscuous on manually for VF XX\".\n\nExact code for stable reproduction Intel can't open-source now.\n\nThe fix involves implementing a new intermediate filter state,\nI40E_FILTER_NEW_SYNC, for the time when a filter is on a tmp_add_list.\nThese filters cannot be deleted from the hash list directly but\nmust be removed using the full process.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-362" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-19T18:15:27Z" diff --git a/advisories/unreviewed/2024/11/GHSA-g4w7-vcv3-f74v/GHSA-g4w7-vcv3-f74v.json b/advisories/unreviewed/2024/11/GHSA-g4w7-vcv3-f74v/GHSA-g4w7-vcv3-f74v.json index 5d8b67b2d1a..316f4694f9a 100644 --- a/advisories/unreviewed/2024/11/GHSA-g4w7-vcv3-f74v/GHSA-g4w7-vcv3-f74v.json +++ b/advisories/unreviewed/2024/11/GHSA-g4w7-vcv3-f74v/GHSA-g4w7-vcv3-f74v.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-gprg-cxw4-4w2h/GHSA-gprg-cxw4-4w2h.json b/advisories/unreviewed/2024/11/GHSA-gprg-cxw4-4w2h/GHSA-gprg-cxw4-4w2h.json index bae43f96b75..c3ee091344c 100644 --- a/advisories/unreviewed/2024/11/GHSA-gprg-cxw4-4w2h/GHSA-gprg-cxw4-4w2h.json +++ b/advisories/unreviewed/2024/11/GHSA-gprg-cxw4-4w2h/GHSA-gprg-cxw4-4w2h.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-gw66-x3q6-f7fv/GHSA-gw66-x3q6-f7fv.json b/advisories/unreviewed/2024/11/GHSA-gw66-x3q6-f7fv/GHSA-gw66-x3q6-f7fv.json new file mode 100644 index 00000000000..e61dbe99099 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-gw66-x3q6-f7fv/GHSA-gw66-x3q6-f7fv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gw66-x3q6-f7fv", + "modified": "2024-11-25T18:33:26Z", + "published": "2024-11-25T18:33:26Z", + "aliases": [ + "CVE-2023-26280" + ], + "details": "IBM Jazz Foundation 7.0.2 and 7.0.3\n\n could allow a user to change their dashboard using a specially crafted HTTP request due to improper access control.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26280" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7176207" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-25T16:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-h2r3-g3cv-6gh5/GHSA-h2r3-g3cv-6gh5.json b/advisories/unreviewed/2024/11/GHSA-h2r3-g3cv-6gh5/GHSA-h2r3-g3cv-6gh5.json index 7da5e5b5fdc..09b129d1b35 100644 --- a/advisories/unreviewed/2024/11/GHSA-h2r3-g3cv-6gh5/GHSA-h2r3-g3cv-6gh5.json +++ b/advisories/unreviewed/2024/11/GHSA-h2r3-g3cv-6gh5/GHSA-h2r3-g3cv-6gh5.json @@ -48,7 +48,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-j75g-24ff-chhq/GHSA-j75g-24ff-chhq.json b/advisories/unreviewed/2024/11/GHSA-j75g-24ff-chhq/GHSA-j75g-24ff-chhq.json index 14d6a40ed20..177b678ce29 100644 --- a/advisories/unreviewed/2024/11/GHSA-j75g-24ff-chhq/GHSA-j75g-24ff-chhq.json +++ b/advisories/unreviewed/2024/11/GHSA-j75g-24ff-chhq/GHSA-j75g-24ff-chhq.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-jq8p-fq36-ccp5/GHSA-jq8p-fq36-ccp5.json b/advisories/unreviewed/2024/11/GHSA-jq8p-fq36-ccp5/GHSA-jq8p-fq36-ccp5.json new file mode 100644 index 00000000000..4e60795979d --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-jq8p-fq36-ccp5/GHSA-jq8p-fq36-ccp5.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jq8p-fq36-ccp5", + "modified": "2024-11-25T18:33:26Z", + "published": "2024-11-25T18:33:26Z", + "aliases": [ + "CVE-2024-11648" + ], + "details": "A vulnerability, which was classified as critical, was found in 1000 Projects Beauty Parlour Management System 1.0. This affects an unknown part of the file /admin/add-customer.php. The manipulation of the argument name leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11648" + }, + { + "type": "WEB", + "url": "https://github.com/Calmgh/CVE/issues/1" + }, + { + "type": "WEB", + "url": "https://1000projects.org" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.285969" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.285969" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.447291" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74", + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-25T01:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-jx75-26p3-gg9h/GHSA-jx75-26p3-gg9h.json b/advisories/unreviewed/2024/11/GHSA-jx75-26p3-gg9h/GHSA-jx75-26p3-gg9h.json index 0c4aa54a882..bec88bbce15 100644 --- a/advisories/unreviewed/2024/11/GHSA-jx75-26p3-gg9h/GHSA-jx75-26p3-gg9h.json +++ b/advisories/unreviewed/2024/11/GHSA-jx75-26p3-gg9h/GHSA-jx75-26p3-gg9h.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-pjh6-pqrj-qmjf/GHSA-pjh6-pqrj-qmjf.json b/advisories/unreviewed/2024/11/GHSA-pjh6-pqrj-qmjf/GHSA-pjh6-pqrj-qmjf.json index 39c4772acee..e7b6d6d54b5 100644 --- a/advisories/unreviewed/2024/11/GHSA-pjh6-pqrj-qmjf/GHSA-pjh6-pqrj-qmjf.json +++ b/advisories/unreviewed/2024/11/GHSA-pjh6-pqrj-qmjf/GHSA-pjh6-pqrj-qmjf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pjh6-pqrj-qmjf", - "modified": "2024-11-19T18:31:07Z", + "modified": "2024-11-25T18:33:25Z", "published": "2024-11-19T18:31:07Z", "aliases": [ "CVE-2024-53078" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/tegra: Fix NULL vs IS_ERR() check in probe()\n\nThe iommu_paging_domain_alloc() function doesn't return NULL pointers,\nit returns error pointers. Update the check to match.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-19T18:15:27Z" diff --git a/advisories/unreviewed/2024/11/GHSA-pvmv-37h8-9j25/GHSA-pvmv-37h8-9j25.json b/advisories/unreviewed/2024/11/GHSA-pvmv-37h8-9j25/GHSA-pvmv-37h8-9j25.json index eddb8b706ec..ddbaead25ee 100644 --- a/advisories/unreviewed/2024/11/GHSA-pvmv-37h8-9j25/GHSA-pvmv-37h8-9j25.json +++ b/advisories/unreviewed/2024/11/GHSA-pvmv-37h8-9j25/GHSA-pvmv-37h8-9j25.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pvmv-37h8-9j25", - "modified": "2024-11-25T06:34:59Z", + "modified": "2024-11-25T18:33:26Z", "published": "2024-11-25T06:34:59Z", "aliases": [ "CVE-2024-6393" ], "details": "The Photo Gallery, Sliders, Proofing and WordPress plugin before 3.59.5 does not sanitise and escape some of its Images settings, which could allow high privilege users such as Admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-25T06:15:06Z" diff --git a/advisories/unreviewed/2024/11/GHSA-qm83-29c6-cf2c/GHSA-qm83-29c6-cf2c.json b/advisories/unreviewed/2024/11/GHSA-qm83-29c6-cf2c/GHSA-qm83-29c6-cf2c.json index de14e1cba34..c7bb1aa59b1 100644 --- a/advisories/unreviewed/2024/11/GHSA-qm83-29c6-cf2c/GHSA-qm83-29c6-cf2c.json +++ b/advisories/unreviewed/2024/11/GHSA-qm83-29c6-cf2c/GHSA-qm83-29c6-cf2c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qm83-29c6-cf2c", - "modified": "2024-11-19T18:31:07Z", + "modified": "2024-11-25T18:33:25Z", "published": "2024-11-19T18:31:07Z", "aliases": [ "CVE-2024-53082" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nvirtio_net: Add hash_key_length check\n\nAdd hash_key_length check in virtnet_probe() to avoid possible out of\nbound errors when setting/reading the hash key.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-19T18:15:27Z" diff --git a/advisories/unreviewed/2024/11/GHSA-qpgc-w4mg-6v92/GHSA-qpgc-w4mg-6v92.json b/advisories/unreviewed/2024/11/GHSA-qpgc-w4mg-6v92/GHSA-qpgc-w4mg-6v92.json new file mode 100644 index 00000000000..50b278183c5 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-qpgc-w4mg-6v92/GHSA-qpgc-w4mg-6v92.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qpgc-w4mg-6v92", + "modified": "2024-11-25T18:33:26Z", + "published": "2024-11-25T18:33:26Z", + "aliases": [ + "CVE-2024-27134" + ], + "details": "Excessive directory permissions in MLflow leads to local privilege escalation when using spark_udf. This behavior can be exploited by a local attacker to gain elevated permissions by using a ToCToU attack. The issue is only relevant when the spark_udf() MLflow API is called.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27134" + }, + { + "type": "WEB", + "url": "https://github.com/mlflow/mlflow/pull/10874" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-276" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-25T14:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-rvwc-2m5x-qrf7/GHSA-rvwc-2m5x-qrf7.json b/advisories/unreviewed/2024/11/GHSA-rvwc-2m5x-qrf7/GHSA-rvwc-2m5x-qrf7.json new file mode 100644 index 00000000000..1b642554000 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-rvwc-2m5x-qrf7/GHSA-rvwc-2m5x-qrf7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rvwc-2m5x-qrf7", + "modified": "2024-11-25T18:33:26Z", + "published": "2024-11-25T18:33:26Z", + "aliases": [ + "CVE-2023-45181" + ], + "details": "IBM Jazz Foundation 7.0.2 and below are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45181" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7176207" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-25T16:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-vgfw-cgxj-f63c/GHSA-vgfw-cgxj-f63c.json b/advisories/unreviewed/2024/11/GHSA-vgfw-cgxj-f63c/GHSA-vgfw-cgxj-f63c.json new file mode 100644 index 00000000000..6840d58e815 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-vgfw-cgxj-f63c/GHSA-vgfw-cgxj-f63c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vgfw-cgxj-f63c", + "modified": "2024-11-25T18:33:26Z", + "published": "2024-11-25T18:33:26Z", + "aliases": [ + "CVE-2024-7915" + ], + "details": "The application Sensei Mac Cleaner contains a local privilege escalation vulnerability, allowing an attacker to perform multiple operations as the root user. These operations include arbitrary file deletion and writing, loading and unloading daemons, manipulating file permissions, and loading extensions, among other actions.\n\n\nThe vulnerable module org.cindori.SenseiHelper can be contacted via XPC. While the module performs client validation, it relies on the client's PID obtained through the public processIdentifier property of the NSXPCConnection class. This approach makes the module susceptible to a PID Reuse Attack, enabling an attacker to impersonate a legitimate client and send crafted XPC messages to invoke arbitrary methods exposed by the HelperProtocol interface.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7915" + }, + { + "type": "WEB", + "url": "https://pentraze.com/vulnerability-reports" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-25T18:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-vwh2-c4wj-6g2g/GHSA-vwh2-c4wj-6g2g.json b/advisories/unreviewed/2024/11/GHSA-vwh2-c4wj-6g2g/GHSA-vwh2-c4wj-6g2g.json new file mode 100644 index 00000000000..2e1517a2819 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-vwh2-c4wj-6g2g/GHSA-vwh2-c4wj-6g2g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vwh2-c4wj-6g2g", + "modified": "2024-11-25T18:33:25Z", + "published": "2024-11-25T18:33:25Z", + "aliases": [ + "CVE-2024-7130" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kion Computer KION Exchange Programs Software allows Reflected XSS.This issue affects KION Exchange Programs Software: before 1.21.9092.29966.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7130" + }, + { + "type": "WEB", + "url": "https://www.usom.gov.tr/bildirim/tr-24-1867" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-21T14:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-w258-w769-3m5g/GHSA-w258-w769-3m5g.json b/advisories/unreviewed/2024/11/GHSA-w258-w769-3m5g/GHSA-w258-w769-3m5g.json new file mode 100644 index 00000000000..34c27c55d29 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-w258-w769-3m5g/GHSA-w258-w769-3m5g.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w258-w769-3m5g", + "modified": "2024-11-25T18:33:26Z", + "published": "2024-11-25T18:33:26Z", + "aliases": [ + "CVE-2024-45755" + ], + "details": "An issue was discovered in Centreon centreon-dsm-server 24.10.x before 24.10.0, 24.04.x before 24.04.3, 23.10.x before 23.10.1, 23.04.x before 23.04.3, and 22.10.x before 22.10.2. SQL injection can occur in the form to configure Centreon DSM slots. Exploitation is only accessible to authenticated users with high-privileged access.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45755" + }, + { + "type": "WEB", + "url": "https://github.com/centreon/centreon/releases" + }, + { + "type": "WEB", + "url": "https://thewatch.centreon.com/latest-security-bulletins-64/cve-2024-45755-centreon-dsm-high-severity-4066" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-25T17:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-w3g2-g4x7-9grg/GHSA-w3g2-g4x7-9grg.json b/advisories/unreviewed/2024/11/GHSA-w3g2-g4x7-9grg/GHSA-w3g2-g4x7-9grg.json index 25566e9b8ef..e38469324e2 100644 --- a/advisories/unreviewed/2024/11/GHSA-w3g2-g4x7-9grg/GHSA-w3g2-g4x7-9grg.json +++ b/advisories/unreviewed/2024/11/GHSA-w3g2-g4x7-9grg/GHSA-w3g2-g4x7-9grg.json @@ -48,7 +48,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-wc63-rvqh-4rvx/GHSA-wc63-rvqh-4rvx.json b/advisories/unreviewed/2024/11/GHSA-wc63-rvqh-4rvx/GHSA-wc63-rvqh-4rvx.json index 23bcf1d63b9..da228986a7c 100644 --- a/advisories/unreviewed/2024/11/GHSA-wc63-rvqh-4rvx/GHSA-wc63-rvqh-4rvx.json +++ b/advisories/unreviewed/2024/11/GHSA-wc63-rvqh-4rvx/GHSA-wc63-rvqh-4rvx.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-wjc3-x7p8-9qfh/GHSA-wjc3-x7p8-9qfh.json b/advisories/unreviewed/2024/11/GHSA-wjc3-x7p8-9qfh/GHSA-wjc3-x7p8-9qfh.json index e3637d02abb..d5cd5991356 100644 --- a/advisories/unreviewed/2024/11/GHSA-wjc3-x7p8-9qfh/GHSA-wjc3-x7p8-9qfh.json +++ b/advisories/unreviewed/2024/11/GHSA-wjc3-x7p8-9qfh/GHSA-wjc3-x7p8-9qfh.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-x2h3-hwfm-chhg/GHSA-x2h3-hwfm-chhg.json b/advisories/unreviewed/2024/11/GHSA-x2h3-hwfm-chhg/GHSA-x2h3-hwfm-chhg.json index b0cee9d4498..1952eec3307 100644 --- a/advisories/unreviewed/2024/11/GHSA-x2h3-hwfm-chhg/GHSA-x2h3-hwfm-chhg.json +++ b/advisories/unreviewed/2024/11/GHSA-x2h3-hwfm-chhg/GHSA-x2h3-hwfm-chhg.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-xfg6-fr73-q2fq/GHSA-xfg6-fr73-q2fq.json b/advisories/unreviewed/2024/11/GHSA-xfg6-fr73-q2fq/GHSA-xfg6-fr73-q2fq.json new file mode 100644 index 00000000000..8034bc60e58 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-xfg6-fr73-q2fq/GHSA-xfg6-fr73-q2fq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xfg6-fr73-q2fq", + "modified": "2024-11-25T18:33:26Z", + "published": "2024-11-25T18:33:26Z", + "aliases": [ + "CVE-2024-11671" + ], + "details": "Improper authentication in SQL data source MFA validation in Devolutions Remote Desktop Manager 2024.3.17 and earlier on Windows allows an authenticated user to bypass the MFA validation via data source switching.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11671" + }, + { + "type": "WEB", + "url": "https://devolutions.net/security/advisories/DEVO-2024-0016" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-25T15:15:07Z" + } +} \ No newline at end of file